CVE Vulnerability Database

Search and browse 397,790 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-7774MEDIUM6.9tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names,...
CVE-2026-5228HIGH8.8Improper Access Control, Missing Authorization vulnerability in Kurt Software Studio WriteUp Mobile App allows Accessing...
CVE-2026-45287MEDIUM5.5OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.0.17, `go.opentelemetry.io/otel/schema/v1...
CVE-2026-44393HIGH7.4An issue was discovered in OpenStack oslo.messaging 1.0.0 through 17.3.0. The oslo.messaging RabbitMQ driver does not pe...
CVE-2026-43986CRITICAL9.9Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose a public ...
CVE-2026-43985HIGH8.8Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose `configUp...
CVE-2026-43984HIGH8.9Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose `log_js_e...
CVE-2026-41178MEDIUM5.3OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1.41.0 and 1.43.0 removed raw-length rejection and ...
CVE-2026-40930MEDIUM5.4LIBPNG is a reference library for use in applications that process PNG (Portable Network Graphics) raster image files. I...
CVE-2026-38570HIGH7.5bacnet_stack 1.3.1 contains an Out-of-bounds Read in bacnet_tag_number_decode which allows attackers to cause a denial o...
CVE-2026-36182CRITICAL9.8GNCC GP5 v7.1.76 was discovered to utilize a weak hashing algorithm to protect the root password, possibly allowing atta...
CVE-2026-10868CRITICAL9A mass assignment vulnerability exists in the MISP user edit functionality due to insufficient filtering of user-supplie...
CVE-2026-10815MEDIUM6.3A vulnerability was found in LakshayD02 Hostel-Management-System-PHP up to f87e67c283bab6f718faf2fec6ae39a13bd7036b. Thi...
CVE-2026-10814HIGH7A vulnerability has been found in milvus-io milvus up to 2.6.13. This vulnerability affects unknown code of the file int...
CVE-2026-10813LOW3.6A flaw has been found in LMCache up to 0.4.6. This affects the function hex_hash_to_int16 of the file lmcache/integratio...
CVE-2026-47707MEDIUM5.3Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.172.0 through0.315.6, the MaxAliasesLimiter ext...
CVE-2026-47706MEDIUM5.3Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.71.0 through 0.315.6, the QueryDepthLimiter ext...
CVE-2026-45739MEDIUM4.3Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.288.4 through 0.315.3, Strawberry's bundled Gra...
CVE-2026-41065HIGH8.9Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 are vulnerable t...
CVE-2026-36180MEDIUM4.6A lack of runtime integrity in GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass file system read-only pr...
CVE-2026-36178MEDIUM4.6The factory reset functionality in GNCC GP5 v7.1.76 fails to clear sensitive cryptographic material in the JFFS2 configu...
CVE-2026-36176HIGH7.1GNCC GP5 v7.1.76 was discovered to store pre-signed Backblaze B2 upload URLs (PUT requests) in plaintext to the serial c...
CVE-2026-36175MEDIUM6.8An issue in the U-Boot component of GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass authentication and ...
CVE-2026-36174MEDIUM4.6GNCC GP5 v7.1.76 was discovered to store sensitive wireless network information in plaintext during routine operations t...
CVE-2026-35906CRITICAL9.6An undocumented debug CGI endpoint in T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03 allows unauthenticated at...